[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f8k8GNkNXDT3dVbfLbqhHu3RkgHEL554GPiU4xYNFgHE":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":48},"ca67608e-3cee-4779-a82c-bb3cea6b8c1a","ai-chatbots-collect-your-data-by-default-know-the-risks","c6c5998e-d9f2-4bbf-b5f6-30da7bb6f2cf","AI Chatbots Collect Your Data by Default — Know the Risks","Popular AI chatbots such as ChatGPT, Claude, and Gemini collect and store user conversations by default, exposing potentially sensitive personal, professional, or financial information to service providers and third parties. Many users are unaware that their interactions may be used for model training, reviewed by human contractors, or subject to data breaches. This matters because employees and individuals routinely share confidential data with AI tools without understanding the privacy implications. Emerging privacy-preserving tools using cryptography signal that the industry is responding, but users cannot wait for the market to catch up — they must take proactive steps now.","**Immediate actions:**\n- Review and disable conversation history and data-sharing settings in all AI chatbot accounts you use today.\n- Avoid entering personally identifiable information (PII), financial data, passwords, or proprietary business data into AI chat interfaces.\n- Opt out of model training data programs where the option is available (e.g., ChatGPT's data controls in settings).\n\n**Long-term improvements:**\n- Establish an organizational policy defining which types of data are prohibited from being entered into third-party AI tools.\n- Evaluate and prefer AI solutions that offer on-premises deployment or verifiable privacy guarantees (e.g., zero-knowledge or end-to-end encrypted services).\n- Conduct regular vendor privacy assessments for any AI tools integrated into business workflows.\n\n**User awareness measures:**\n- Train employees on the data retention and usage policies of AI tools before allowing their use in a work context.\n- Publish internal guidance distinguishing between approved and unapproved AI platforms based on data sensitivity classification.\n- Monitor emerging regulatory requirements (e.g., EU AI Act, GDPR) and adjust acceptable-use policies accordingly.",[12,13,14,15,16,17,18,19,20,21],"NIST SP 800-53 AC-3 (Access Enforcement)","NIST SP 800-53 PT-1 (Personally Identifiable Information Processing Policy)","NIST Privacy Framework PR.PO-P1 (Policies for data processing)","GDPR Article 5 (Principles relating to processing of personal data)","GDPR Article 13 (Transparency – right to information)","GDPR Article 25 (Data protection by design and by default)","CIS Control 3 (Data Protection)","CIS Control 14 (Security Awareness and Skills Training)","ISO\u002FIEC 27001 Annex A.8.2 (Information Classification)","NIST AI RMF (AI Risk Management Framework) – GOVERN 1.1","published","2026-09-22T10:20:21.550779+00:00","2026-09-22T10:20:21.204+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fwww.wired.com\u002Fstory\u002Fhow-to-use-ai-with-your-privacy-intact\u002F","how-to-use-ai-with-your-privacy-intact-a77bb0","How to Use AI With Your Privacy Intact",[30,36,42],{"id":31,"name":32,"slug":33,"description":34,"color":35},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":37,"name":38,"slug":39,"description":40,"color":41},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",{"id":43,"name":44,"slug":45,"description":46,"color":47},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]